Junglewise Threat Intelligence

CVE-2023-23529: Apple Multiple Products WebKit Type Confusion Vulnerability

CVE-2023-23529 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-02-14

Technologies: Apple Safari, Apple macOS Ventura, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

A type confusion vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved checks and state management across multiple Apple operating systems and the Safari browser.

Affected products

  • Apple WebKit
  • Apple Safari before 16.3
  • Apple iOS before 15.7.4, 16.0 to before 16.3.1
  • Apple iPadOS before 15.7.4, 16.0 to before 16.3.1
  • Apple macOS Ventura 13.0 to before 13.2.1

Timeline

  • 2023-02-14: disclosed
  • 2023-02-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-14: patched: Fixed in iOS/iPadOS 16.3.1, macOS 13.2.1, and Safari 16.3
  • 2023-02-14: exploited: Apple reported awareness of active exploitation at time of release.

Related threats